Leviathan

MITRE ATT&CK: G0065 View on attack.mitre.org

Aliases: MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK, TEMP.Jumper, APT40, TEMP.Periscope, Gingham Typhoon, Leviathan, GADOLINIUM, KRYPTONITE PANDA, ATK29, TA423, Red Ladon, ITG09, ISLANDDREAMS, JJDoor, Feverdream

First seen
2009-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
118 (115 malicious)
Last IoC activity
2026-09-02 00:38:30
Profile updated
2026-07-07 12:33:00

Targeted industries: defense-and-aerospace education-and-nonprofits healthcare-and-pharmaceutical government-and-public-sector manufacturing transportation-and-logistics

Targeted regions: country_code:us country_code:ca country_code:au country_code:cn country_code:gb country_code:fr country_code:de

Context

Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company. Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.

Recent IoC activity

115 malicious indicators in Maltiverse are attributed to Leviathan (G0065). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname www.nullsecurity.net 2026-09-03 1
hostname ns-3.open.ro 2026-09-03 1
hostname autodiscover.email 2026-09-03 1
hostname autodiscover.exchange 2026-09-03 1
hostname ultrasocial.info 2026-09-03 2
hostname autoconfig.email 2026-09-03 1
hostname usdagroup.com 2026-09-03 3
hostname mail.pics 2026-09-03 1
hostname prod.tools 2026-09-02 1
hostname webdisk.us 2026-09-02 1
hostname autodiscover.host 2026-09-02 1
hostname admin.dev 2026-09-02 1
hostname airbusocean.com 2026-09-02 3
hostname autodiscover.it 2026-09-02 1
hostname made.by 2026-09-02 1
hostname thyssenkrupp-marinesystems.org 2026-09-02 4
hostname www.cantrip.org 2026-09-02 1
hostname test.support 2026-09-02 1
hostname mail.news 2026-09-02 1
hostname webdisk.it 2026-09-02 1

Detection coverage

  • 155 YARA rules
  • 821 Sigma rules

Malware & tools used

  • Exfiltration to Cloud Storage (attack-pattern)
  • Vulnerability Scanning (attack-pattern)
  • One-Way Communication (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • SSH (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Credentials (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Social Media Accounts (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Binary Padding (attack-pattern)
  • Domains (attack-pattern)
  • Email Accounts (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Windows Management Instrumentation Event Subscription (attack-pattern)
  • Steganography (attack-pattern)
  • Social Media Accounts (attack-pattern)
  • PowerShell (attack-pattern)
  • Shortcut Modification (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Server (attack-pattern)

Related threat objects

Reports & references

  • Mandiant — Apt Groups (report)
  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • CrowdStrike — Two Birds One Stone Panda (report)
  • Microsoft — Rwmfii (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • CrowdStrike — 2019 Crowdstrike Global Threat Report (report)
  • proofpoint.com — Leviathan Espionage Actor Spearphishes Maritime And Defense Targets (report)
  • Mandiant — Suspected Chinese Espionage Group Targeting Maritime And Engineering Industries (report)
  • cfr.org — Apt 40 (report)
  • Mandiant — Apt40 Examining A China Nexus Espionage Actor (report)
  • recordedfuture.com — Chinese Threat Actor Tempperiscope (report)
  • Mandiant — Chinese Espionage Group Targets Cambodia Ahead Of Elections (report)
  • MITRE ATT&CK — G0065 (report)
  • intrusiontruth.wordpress.com — What Is The Hainan Xiandun Technology Development Company (report)
  • intrusiontruth.wordpress.com — Who Is Mr Gu (report)
  • intrusiontruth.wordpress.com — Who Else Works For This Cover Company Network (report)
  • intrusiontruth.wordpress.com — Who Is Mr Ding (report)
  • intrusiontruth.wordpress.com — Hainan Xiandun Technology Company Is Apt40 (report)
  • secureworks.com — Bronze Mohawk (report)
  • mycert.org.my — Advisory (report)
  • elastic.co — Advanced Techniques Used In Malaysian Focused Apt Campaign (report)
  • Microsoft — Gadolinium Detecting Empires Cloud (report)
  • justice.gov — Four Chinese Nationals Working Ministry State Security Charged Global Computer Intrusion (report)
  • justice.gov — Download (report)
  • justice.gov — Download (report)

Attributed from

  • APT40 Recent Tradecraft (Deprecated) (campaign)
  • Leviathan Australian Intrusions (campaign)

External references